Azure Virtual Network Manager: diagnose a Security Admin rule before changing NSGs
A production runbook for identifying an Azure Virtual Network Manager Security Admin rule, separating Allow, Always Allow and Deny, then validating or rolling back the deployment without blindly opening NSGs.
Read article